Overview of Information Handling
Personal information may be processed for different purposes depending on how a visitor interacts with the website. The table below provides a general overview rather than a list of mandatory data collection practices.
| Area | How Information May Be Handled |
| Types of data | Contact details, account information, technical data, transaction-related records, and user communications |
| Processing purposes | Website operation, account functions, security, support, fraud prevention, and service improvement |
| Sources | Information entered by users, website interactions, devices, browsers, and relevant service providers |
| Cookies | Technologies may support sessions, preferences, security, and website analytics |
| Possible recipients | Hosting, security, payment, support, or other technical service providers where required |
| Retention | Storage periods may depend on purpose, legal requirements, security needs, and disputes |
| Security | Access controls, monitoring, secure transmission measures, and account protections may be used |
| User choices | Users may be able to request access, correction, deletion, restriction, or withdrawal of consent |
| Contact | Privacy-related requests may be submitted through the available website contact channel |
For users in Bangladesh, personal-data processing may also be affected by the Personal Data Protection Act, 2026. The law includes requirements relating to lawful processing, transparency, security, consent, and certain rights of data holders.
When This Policy Applies
This policy may apply whenever a person interacts with the website in a way that involves personal or technical information.
Examples can include:
- Visiting or navigating website pages;
- Creating or using an account where account functionality is available;
- Changing profile or preference settings;
- Using interactive website features;
- Sending a question or support request;
- Submitting information through a contact form;
- Interacting with security or verification procedures where applicable.
The policy applies to information processed through this website rather than automatically covering every external platform mentioned or linked in its content.
Third-party websites, payment services, applications, advertising systems, or other external resources may operate under their own privacy policies. Users should review those policies before submitting personal or financial information outside this website.
Types of Personal Data
The website may process different categories of information depending on the functions being used. Not every category described below is necessarily collected from every visitor.
Personal information may include:
- Contact information, such as an email address or other details voluntarily provided by the user;
- Account information, where registration or profile functionality exists;
- Technical information generated when a device connects to the website;
- Transaction-related information, where a feature involves a payment or other financial interaction;
- Communications, including enquiries, feedback, or support messages;
- Security information used to detect suspicious access, misuse, or other technical risks.
Only information relevant to a particular interaction should be requested or processed where practicable.
Account and Profile Details
Where the website offers account functionality, users may provide information associated with their profile.
Depending on the service, this could include a username, contact details, country of residence, date of birth, profile preferences, or other information entered voluntarily.
This section does not mean that every listed item is an obligatory registration field. The information required can depend on the specific website function and the rules applicable to that function.
Users should provide accurate information when an account feature depends on it and should update relevant details when they change.
Verification Information
Certain website functions may require information that helps confirm identity, age, account ownership, or the legitimacy of a particular activity.
The nature of verification can vary. Users should provide sensitive identification information only through the designated secure channel associated with the relevant process.
Verification information should not be sent through unofficial social-media accounts, unverified email addresses, public comments, or other channels that are not intended to receive sensitive documents.
Transaction Information
If the website includes functions involving transactions, limited information connected with those activities may be processed.
This could include a transaction reference, payment status, amount, time, or related account record where such information is necessary to operate a feature, respond to an enquiry, maintain security, or resolve a dispute.
Full payment credentials may also be handled separately by an external payment provider rather than directly through the website. The exact arrangement depends on the service used.
Automatically Collected Technical Data
Some technical information may be generated automatically when a person visits the website.
Such data can include:
- IP address;
- Browser type and version;
- Device type;
- Operating system;
- Language settings;
- Pages visited;
- Approximate interaction times;
- Session and diagnostic information.
Technical data may help maintain website functionality, identify errors, improve page performance, understand general usage patterns, and protect the resource against suspicious activity.
Automatically collected information should not be interpreted as proof that the website knows the real-world identity of every visitor.
Reasons for Processing Information
Personal information may be processed where it is reasonably connected to the operation, security, or improvement of the website.
Common purposes can include account administration, responding to users, providing requested functions, preventing misuse, investigating technical incidents, and improving website performance.
| Processing Purpose | Typical Reason |
| Account operation | To provide and maintain user-related functionality |
| User support | To respond to questions, requests, or technical problems |
| Security | To identify suspicious activity and protect accounts or infrastructure |
| Verification | To confirm information where a legitimate verification process applies |
| Website improvement | To understand performance and improve usability |
| Abuse prevention | To detect fraud, automated attacks, or prohibited activity |
| Compliance | To respond to applicable legal or regulatory obligations |
Where processing depends on consent, users should be given appropriate information about the relevant purpose. Bangladesh’s current personal-data framework provides that consent should be informed, specific, clear, voluntary, and capable of withdrawal, subject to applicable lawful grounds for processing.
Cookies and Website Technologies
Cookies and similar technologies may be used to support website functionality.
Some cookies are necessary for technical functions. For example, they may help maintain a session, remember security-related information, or preserve settings while a user moves between pages.
Other technologies may be used for analytics, such as understanding which pages receive visits or how users interact with website features.
A simple distinction is:
- Essential technologies support functions required for the website to work correctly or securely.
- Analytical technologies help assess performance, usage patterns, and possible improvements.
The precise cookies in use can change as website functionality develops.
Managing Cookie Settings
Users can usually manage cookies through their browser settings. Depending on the browser, it may be possible to delete stored cookies, block future cookies, restrict third-party cookies, or receive notifications before certain technologies are stored.
Blocking cookies can affect functionality. Login sessions, saved preferences, security controls, or interactive tools may not work as expected when essential technologies are disabled.
Browser controls therefore give users additional privacy choices but can also change how the website behaves.
Sharing Data With Service Providers
A website may rely on technical suppliers to provide certain functions.
Where necessary, a limited amount of information may be processed by providers supporting areas such as:
- Website hosting and infrastructure;
- Security and fraud prevention;
- Payment-related functionality;
- Technical maintenance;
- Customer or user support;
- Analytics and performance monitoring.
Access should be limited to information reasonably required for the relevant service.
Mentioning these categories does not mean that every type of provider is used by the website. Specific companies should not be assumed unless they are identified through an appropriate notice or another confirmed source.
Required Disclosures and Security Needs
Personal information may sometimes need to be disclosed where there is a valid legal requirement or a legitimate need to protect users, systems, or rights.
Possible situations can include responding to a lawful order, investigating suspected fraud, addressing security incidents, protecting against abuse, or establishing and defending legal claims.
Such disclosure should be limited to what is appropriate for the relevant purpose and applicable rules.
Bangladesh’s Personal Data Protection Act, 2026 also establishes security and confidentiality obligations for entities responsible for processing personal information. Appropriate technical and organisational measures are expected to address risks such as unauthorised access, unlawful disclosure, loss, misuse, or alteration.
International Data Processing
Some technical services may operate across more than one region. As a result, information may in certain circumstances be processed or stored outside the location where the user originally accessed the website.
Any such processing should be handled under the safeguards and legal requirements applicable to the particular data and transfer.
The existence of international technical infrastructure does not automatically mean that all user information is transferred abroad.
Bangladesh’s current personal-data legislation contains specific provisions governing certain transfers of personal data outside the country.
Data Storage Periods
Personal information should not be retained simply because it has been collected.
The appropriate storage period can depend on:
- The reason the information was collected;
- Whether an account or service relationship remains active;
- Security and fraud-prevention requirements;
- The need to resolve complaints or disputes;
- Applicable record-keeping obligations;
- Whether the data can be deleted or anonymised after its purpose ends.
For these reasons, one fixed retention period should not be assumed for every category of information.
When information is no longer required, appropriate deletion, anonymisation, or other disposal measures may be applied according to the relevant circumstances and applicable requirements.
Protecting User Information
Reasonable technical and organisational measures may be used to protect personal information.
These can include controlled access to administrative systems, account-security procedures, monitoring for suspicious activity, secure data transmission, internal access restrictions, and measures intended to reduce unauthorised disclosure.
No online system can provide an absolute guarantee against every security risk. Users also play a role in protecting their information by choosing strong passwords, keeping login credentials private, protecting verification codes, and avoiding suspicious links or unofficial communication channels.
User Privacy Choices
Depending on the circumstances and applicable rules, users may have privacy choices concerning their personal information.
These can include the ability to:
- Request access to personal information associated with them;
- Ask for incorrect or incomplete information to be corrected;
- Request deletion where the information no longer needs to be retained;
- Object to or request restrictions on certain processing;
- Withdraw consent where processing depends on consent;
- Ask for information about how their data is being handled.
The Personal Data Protection Act, 2026 provides rights relating to access, correction, consent withdrawal and, in qualifying situations, deletion of personal data.
Updating Personal Details
Where account settings allow editing, users may be able to update some profile information directly.
If a particular field cannot be changed through the account interface, a correction request may be submitted through an available contact or support channel.
Additional verification may be appropriate before significant account information is changed in order to prevent unauthorised modifications.
Removing Personal Information
A user may be able to request deletion of personal information when the relevant conditions are met.
Deletion is not necessarily unconditional. Some information may need to remain available where retention is required for legal compliance, security, dispute resolution, fraud prevention, or another valid purpose.
Where deletion is appropriate, the relevant information should be removed or otherwise handled according to applicable requirements.
Managing Consent Preferences
Where a specific type of processing is based on user consent, that consent may be capable of withdrawal.
Withdrawal can affect future processing connected with that consent, but it does not necessarily invalidate processing that was lawful before the withdrawal occurred.
Users can submit privacy-related requests through the contact methods made available by the website. Requests may require reasonable verification to help ensure that personal information is not disclosed, modified, or deleted at the request of an unauthorised person.

Deposit Now!
Jaya9 Bonus